ended4월 4일· 4 sources

OpenClaw Critical Flaw: How a Single Validation Bug Exposed 135K Instances

OpenClaw 심각한 결함: 페어링 검증 미흡으로 13.5만 인스턴스 위험

Why it matters

OpenClaw's pairing approval mechanism fails to validate user permissions, allowing anyone with basic access to grant themselves admin rights in under 30 seconds. With 135,000+ instances publicly exposed and 63% running zero authentication, the trivial exploit path has almost certainly been weaponized since the two-day window between patch and public disclosure. Immediate patching to version 2026.3.28 and forensic auditing are essential for all affected organizations.

4
Sources
+0
24h
Growth
170d
Active
ai agentauthentication bypassauthorization bypasscve-2026-33579device pairingopenclawprivilege escalationscope validationsecurity patch

Sources

Related Issues